Home / Companies / Elastic / Blog / Post Details
Content Deep Dive

Normalizing your custom data sources to Elastic Common Schema

Blog post from Elastic

Post Details
Company
Date Published
Author
-
Word Count
663
Company Posts That Month
33
Language
-
Hacker News Points
-
Post removed?
No
Summary

The Elastic Common Schema (ECS) offers a standardized model for organizing data within the Elastic Stack, facilitating consistent examination through search, visualizations, and automated analysis. While Elastic provides numerous integrations that adhere to ECS standards, custom data sources can also be normalized to this schema, though it can be a time-consuming process. The Elastic Security detection engine aids in identifying ECS non-compliance, generating alerts for events lacking the ecs.version field or using improper field values. Detection rules can also ensure that network events have both source and destination fields populated, and that fields processed by ingest pipelines, such as user agent fields, are complete. These detection rules help refine data ingestion by promptly highlighting non-compliant events, which can be addressed systematically. A free trial of Elastic Cloud is available for users to experiment with these detection rules and improve ECS compliance in their data processes.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Data Pipeline 1 221 42 23 +89%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.